From 9bf05c8b6dc5a1e7afabce07b38259d4d5021828 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 16:39:09 +0000 Subject: [PATCH] Ledger 2.0 D5: proofs are a condition of payment in the node behind the switch, team-tested, awaiting the live read on igneum-devnet-4 Co-Authored-By: Claude Fable 5.1 --- docs/fud-ledger-2.0.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/fud-ledger-2.0.md b/docs/fud-ledger-2.0.md index 87ea43380..03fa961b6 100644 --- a/docs/fud-ledger-2.0.md +++ b/docs/fud-ledger-2.0.md @@ -110,7 +110,7 @@ Pin: D4, first, fifth to seventh boxes and the pass condition. ### D5. Proofs are not a protocol guarantee yet "Proof verification sits off the consensus path. A modified producer can include a matching statement without the valid proof and collect a payout it did not earn." -Status: Conceded (8 October 2026): consensus does not enforce proofs today; the switch is in the node and reads never on the devnet. Pass when proof verification is enforced in consensus, live on the exercise network. +Status: Fixed in the node, awaiting the live read (8 October 2026, 17:4x UK): a valid SP1 proof is a condition of payment in consensus behind the named switch `verifier_in_consensus` (`docs/spec/proving-enforcement.md`): the body rule refuses a block whose carried proof is not held, does not verify or names another program id, and the executor pays a record only with a verified proof. The switch is false on every compiled object, so Devnet 3's digest never moved; the igneum-devnet-4 object of node 2.0.0 is cut with it on from block zero (the shipper's line, release-2.0.0-node). Team-tested: the seven refusals and the plan's six negative tests as named tests (rows 1 to 5 covered; row 6 team-tested for the native veto and PENDING for the proof side), suites green on build-2 at 16:15 UK, the fast-time crossing PASS at 17:22 UK (the forged record paid below the floor, refused and unpaid at it). Pass when the rule is read live on the exercise network: the daemon's start line with `verifier_in_consensus set` and a refused forged record in the journal. Was: Conceded (8 October 2026): consensus does not enforce proofs today; the switch is in the node and reads never on the devnet. Status: Fixed (8 October 2026, 17:0x UK): the Igneum 2.0 devnet's node enforces proof verification in consensus from block zero (verifier_in_consensus set, node 2.0.0 4cdcc488 on release-2.0.0-node, the node's own start line); the no-rescue exercise itself stays Open and is the pass condition. Was: Conceded, the rule off on the earlier devnet.